Directory traversal vulnerability in sql.php in phpMyAdmin 3.4.x before 3.4.3.2, when configuration storage is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a MIME-type transformation parameter.
| Software | From | Fixed in |
|---|---|---|
phpmyadmin / phpmyadmin
|
3.4.0.0 | 3.4.0.0.x |
phpmyadmin / phpmyadmin
|
3.4.3.1 | 3.4.3.1.x |
phpmyadmin / phpmyadmin
|
3.4.1.0 | 3.4.1.0.x |
phpmyadmin / phpmyadmin
|
3.4.2.0 | 3.4.2.0.x |
phpmyadmin / phpmyadmin
|
3.4.3.0 | 3.4.3.0.x |